13.07.2015 Views

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

Installing CA Enterprise Log Manager - CA Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Glossaryaccess filteraccess policyaccountaction alertaction queryAdministrator roleagentAn access filter is a filter that the Administrator can set to control what eventdata non-Administrator users or groups can view. For example, an access filtercan restrict the data specified identities can view in a report. Access filters areautomatically converted into obligation policies.An access policy is a rule that grants or denies an identity (user or user group)access rights to an application resource. <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> determineswhether policies apply to the particular user by matching identities, resources,resource classes, and evaluating the filters.An account is a global user who is also a <strong>CA</strong>LM application user. A single personcould have more than one account, each with a different user-defined role.An action alert is a scheduled query job, which can be used to detect policyviolations, usage trends, login patterns, and other event actions that requirenear-term attention. By default, when the alert queries return results, the resultsare displayed on the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> Alerts page and are also addedto an RSS Feed. When you schedule an alert, you can specify additionaldestinations, including email, a <strong>CA</strong> IT PAM event/alert output process, and SNMPtraps.An action query is a query that supports an Action Alert. It is run on a recurringschedule to test for the conditions outlined by the Action Alert to which it isattached.The Administrator role grants users the ability to perform all valid actions on all<strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> resources. Only Administrators are permitted toconfigure log collection and services or manage users, access policies, andaccess filters.An agent is a generic service configured with connectors, each of which collectsraw events from a single event source and then sends them to a <strong>CA</strong> <strong>Enterprise</strong><strong>Log</strong> <strong>Manager</strong> for processing. Each <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong> <strong>Manager</strong> has an onboardagent. Additionally, you can install an agent on a remote collection point andcollect events on hosts where agents cannot be installed. You can also install anagent on the host where event sources are running and benefit from the ability toapply suppression rules and encrypt transmission to the <strong>CA</strong> <strong>Enterprise</strong> <strong>Log</strong><strong>Manager</strong>.Glossary 249

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!